Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

CCPA penalties explained

CCPA Penalties: The 4 Fine Channels and 2025 Amounts Explained

CCPA penalties are set per violation, not per case, and that is the arithmetic every California privacy budget has to start from. Since the 2025 inflation adjustment the administrative fine under Civil Code section 1798.155 is up to $2,663 for each violation, or $7,988 for each intentional violation and each violation involving the personal information of a consumer the business knows is under 16; the Attorney General’s civil penalties under section 1798.199.90 carry the same amounts; and the private right of action under section 1798.150 — for data breaches caused by a failure to maintain reasonable security — is $107 to $799 per consumer per incident, or actual damages if greater. The 30-day cure period that softened the original statute was removed on 1 January 2023. The California Privacy Protection Agency has been issuing decisions since 2024, and its largest to date is $1.35 million. This guide sets out the four penalty channels and their amounts, how “per violation” is counted, the Delete Act’s per-day fines that sit beside them, the enforcement record from Honda to the 2026 data broker actions, the conduct the Agency has actually fined, and how to reduce exposure before a complaint arrives.

CCPA penalties: the four channels and the 2025 amounts
CPPA administrative fines §1798.155: $2,663 / $7,988 per violation · AG civil penalties §1798.199.90: same · private action §1798.150: $107–$799 per consumer per incident for breaches · Delete Act: $200 per day; no cure period since 1 Jan 2023.

The four CCPA penalties channels

Channel Who brings it Amount (effective 1 January 2025) Scope
Administrative fine, Civil Code § 1798.155 The California Privacy Protection Agency, by decision of its Board after an Enforcement Division investigation and, if contested, an administrative hearing Up to $2,663 per violation; up to $7,988 per intentional violation or violation involving a consumer known to be under 16 Any violation of the CCPA or the regulations
Civil penalty, § 1798.199.90 The Attorney General, in a civil action The same amounts, recovered in court Any violation of the CCPA or the regulations
Private right of action, § 1798.150 Consumers, individually or as a class $107 to $799 per consumer per incident, or actual damages, whichever is greater; plus injunctive relief Only a breach of non-encrypted, non-redacted personal information caused by a failure to implement reasonable security; a 30-day written notice and cure applies to statutory damages claims
Delete Act fines, § 1798.99.82 The Agency $200 per day for failing to register; $200 per deletion request per day for failing to delete; plus unpaid fees and costs Data brokers only

The amounts are indexed: section 1798.199.95 adjusts them every odd-numbered year for the California consumer price index, which is how $2,500 and $7,500 became $2,663 and $7,988, and $100 to $750 became $107 to $799, from 1 January 2025. The next adjustment falls on 1 January 2027. Our guide to CCPA compliance covers the obligations the penalties attach to.

How CCPA penalties are counted per violation

The statute does not define the unit, and the Agency’s decisions show the practical answer: a violation is generally a failure with respect to a consumer or a request, so a broken opt-out mechanism that ran for 40 days is not one violation but one for every Californian whose request failed in the period. The $345,178 Todd Snyder fine in May 2025 was built that way — a misconfigured privacy portal that failed to process opt-out requests for 40 days, plus excessive verification demands — and the Board’s decisions describe the count. The intentional tier and the under-16 tier triple the per-unit amount, which is why children’s data and knowing non-compliance are the two facts that change a settlement’s order of magnitude. The absence of a cure period since 2023 means the count starts on the day of the violation, not the day of the notice.

The CCPA penalties record

Date Respondent Amount Conduct
November 2024 – January 2025 Several data brokers Settlements for failure to register Delete Act registration
12 March 2025 American Honda Motor Co. $632,500 Excessive verification for opt-out and limit requests; a privacy management tool that did not offer choices symmetrically; obstacles to authorised agents
6 May 2025 Todd Snyder, Inc. $345,178 Privacy portal failed to process opt-outs for 40 days; excess information demanded; verification required for opt-outs
30 September 2025 Tractor Supply Company $1,350,000 — the Agency’s largest No compliant privacy policy; job applicants not notified of their rights; the first decision on applicants’ privacy rights
3 December 2025 ROR Partners LLC $56,600 in fines and past-due fees Marketing firm operating as an unregistered data broker; first case from the Data Broker Enforcement Strike Force
11 August 2026 LocateSmarter LLC $116,490 First decision under both the CCPA and the Delete Act: late registration and demanding partial Social Security numbers before opt-outs
13 August 2026 Cybba, Inc. $52,400 Failure to register by the 2025 deadline; ordered to process requests through DROP
1 September 2026 SalesIntel Research, Inc. $36,400 Failure to register timely; ordered onto DROP

Two patterns run through the CCPA penalties record. The Agency’s CCPA cases have concentrated on the mechanics of consumer rights — opt-outs that do not work, verification demanded where the statute forbids it, notices missing for a population such as applicants — rather than on data-security failures, which the private right of action polices. And the Delete Act cases show a deliberate escalation: registration failures first, then combined actions, with a strike force announced in November 2025 and an enforcement advisory on inaccurate registrations in September 2026. Our guide to the California Delete Act covers the DROP obligations behind those cases.

What the Agency has actually fined

  1. Opt-outs that require verification. The regulations prohibit requiring a consumer to verify identity to opt out of sale or sharing; Honda, Todd Snyder and LocateSmarter were all fined for it.
  2. Asymmetric choices. A privacy management tool that makes accepting easier than declining is a dark pattern; Honda’s was the example.
  3. Excess information at intake. Asking for more than the statute allows to process a request — down to partial Social Security numbers.
  4. Broken portals. A technical failure that silently dropped requests for weeks was counted per consumer.
  5. Missing notices. A privacy policy that did not state the rights, and no notice at collection for job applicants.
  6. Not registering as a data broker. The cheapest violation to avoid and the most frequently fined.

The private right of action in numbers

The largest of the CCPA penalties is the one regulators do not impose. Section 1798.150 is narrow in scope and large in arithmetic. It applies only to a breach of personal information that is neither encrypted nor redacted, caused by the business’s failure to implement and maintain reasonable security procedures; the consumer must give 30 days’ written notice before claiming statutory damages, and a business that cures within the period and gives a written statement can defeat that claim. But the damages are $107 to $799 per consumer per incident, and class actions multiply them across the affected population: a breach affecting 100,000 Californians carries a statutory-damages range of $10.7 million to $79.9 million before actual damages are considered. It is the reason the CCPA cybersecurity audit regulations, whose first reports fall due in 2028, matter to the litigation budget as much as to the compliance one; our guide to the CCPA cybersecurity audit covers them.

Reducing exposure to CCPA penalties

  • Test the opt-out end to end monthly, including Global Privacy Control signals, and log the test; a 40-day silent failure is the Todd Snyder case.
  • Remove verification from opt-out and limit requests and cut intake forms to the minimum.
  • Make consent tools symmetrical — the same number of clicks to decline as to accept.
  • Cover the workforce and applicants with notices at collection and a privacy policy that states the rights.
  • Answer the Agency. A subpoena enforcement action against a Fortune 500 company in August 2025 shows that non-response is itself litigated.
  • Encrypt and redact, because section 1798.150 does not reach encrypted data, and document reasonable security against the 18 audit components.

Frequently asked questions

What are the CCPA penalties?
Administrative fines by the California Privacy Protection Agency and civil penalties by the Attorney General of up to $2,663 per violation, or $7,988 per intentional violation or violation involving a consumer known to be under 16, since the 1 January 2025 adjustment; statutory damages of $107 to $799 per consumer per incident in private actions over data breaches; and Delete Act fines of $200 per day for data brokers that fail to register or delete.

Is there still a cure period?
Not for regulator enforcement — the 30-day cure period was removed on 1 January 2023. A 30-day notice-and-cure step remains for statutory-damages claims under the private right of action.

What is the largest CCPA fine so far?
The Agency’s $1.35 million decision against Tractor Supply Company on 30 September 2025, for a non-compliant privacy policy and failure to notify job applicants of their rights.

Can consumers sue for any CCPA violation?
No. Section 1798.150 covers only breaches of unencrypted, unredacted personal information caused by a failure to maintain reasonable security; other violations are enforced by the Agency and the Attorney General.

How are violations counted?
The Agency’s decisions treat each affected consumer or request as a violation, so a systemic failure is multiplied by the number of Californians it affected.

Where this leaves you

Budget CCPA penalties as multiplication: the per-violation amount times the consumers affected, tripled for intent or children, with no cure period, and a breach class action at $107 to $799 a head on top. The Agency’s record says where the multiplier is applied — opt-outs, verification, notices, applicants, registration — so test those first, and treat the data broker question as a daily-fine question rather than a definitional one.

References

More on the CCPA

The Consumer Request Intake and Verification Procedure, the Right to Opt-Out of Sale/Sharing Procedure, the Privacy Notice Policy, the Data Breach Response Procedure and the CCPA/CPRA Compliance Checklist are in the CCPA-CPRA Compliance Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.